T09 · Insecure Skill Coding Practices
- Location
scripts/common/drugflow_api.py:9- Finding
Credentials and session cookies may be exposed through insecure transport, command-line arguments, and predictable temporary files
- Content
View full analysis
str: value = (base_url or "").strip() if not value: raise ValueError("base_url cannot be empty") if not value.startswith(("http://", "https://")): value = f"https://{value}" return value.rstrip("/") ``` The password is subsequently submitted to the selected endpoint: ```python def signin(self, email: str, password: str, phone: Optional[str] = None) -> Dict[str, Any]: payload_data: Dict[str, str] = { "email": email, "password": password, # Some deployments keep LoginUserForm.phone as required even for email login. "phone": phone or "0", } payload = self.request_or_raise( "POST", "/signin", data=payload_data, ) if payload.get("detail") != "ok": raise RuntimeError(f"signin did not return detail=ok: {payload}") return payload ``` All remote-flow scripts require the password as a command-line argument. For example: ```python parser.add_argument("--base-url", required=True, help="Example: http://127.0.0.1:8888") parser.add_argument("--email", required=True) parser.add_argument(" ...[truncated 3413 chars]- Remediation
View remediation
